Impact
NVIDIA GPU Display Driver for Windows and Linux contains a kernel‑mode out‑of‑bounds write vulnerability as described in CWE‑787. An attacker who can trigger this flaw may overwrite memory outside the intended bounds, leading to code execution, privilege escalation, denial of service, information disclosure, or data tampering.
Affected Systems
The flaw impacts NVIDIA GPU products including GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager across both Windows and Linux operating systems. No specific driver version ranges are listed, so any installation of the affected driver family is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, and although an EPSS score is not provided, the lack of a readily available mitigation suggests risk remains. The flaw exists in the kernel component, implying that exploitation likely requires local privileges or the ability to send crafted data to the driver, such as through a malicious application or firmware. If an attacker gains enough access to the GPU interface, they could execute arbitrary code with kernel privileges.
OpenCVE Enrichment